Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Guide categories

Operating Systems

Software updates and the security window

Why updates matter, how to make them routine, and how to handle devices that no longer receive security fixes.

The security window

An update closes some known problems; it does not make a device permanently secure. The useful question is whether a device is receiving fixes in time for the threats that matter to you. A device that no longer receives security updates belongs in a different threat model from a current device.

Enable automatic updates where they are reliable and compatible with your work. If updates must be managed manually, choose a regular schedule and check the operating system, browser, firmware, applications and extensions separately.

What to do when an update breaks something

Do not disable updates permanently because of one failure. Keep a tested backup, read the vendor’s release notes, and separate the affected device from sensitive work until a fix is available. A temporary delay can be reasonable; an indefinite delay turns a known vulnerability into a standing exposure.

Retire unsupported devices

If a phone, router, browser or operating system has reached end of support, replace it or isolate it from sensitive activity. Removing unused software and accounts reduces the attack surface but does not replace security patches.

Sources

  1. Update software Cybersecurity and Infrastructure Security Agency government Accessed
  2. Common Vulnerabilities and Exposures MITRE docs Accessed
  • Archive security incidents

    Log4Shell (CVE-2021-44228) (Archive)

    A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.

    10 Dec 2021

  • Archive security incidents

    Heartbleed (CVE-2014-0160) (Archive)

    A missing bounds check in OpenSSL that let a remote client read process memory, and the two years of unmonitored exploitation it enabled.

    7 Apr 2014